CVE-2026-90988
Received Received - Intake

Unauthenticated Access to Quote Records in Request a Quote WordPress Plugin

Vulnerability report for CVE-2026-90988, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: WPScan

Description

The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to read the contact records of quote-request submissions, including records the site has not published.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
artus_kg request_a_quote to 2.5.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-90988 is a vulnerability in the WordPress plugin 'Request a Quote' version 2.5.6 or below. It allows unauthenticated users to access and disclose contact records from quote-request submissions, including unpublished records, due to a missing authorization check on an unauthenticated AJAX handler named emd_get_std_pagenum.

Detection Guidance

To detect this vulnerability, check if the WordPress plugin 'Request a Quote' version 2.5.6 or below is installed. You can verify this by inspecting the plugin files or using WordPress admin panel. No specific commands are provided in the context, but monitoring for unauthorized access to quote records or AJAX handler emd_get_std_pagenum may indicate exploitation.

Impact Analysis

This vulnerability allows unauthorized individuals to read sensitive contact information submitted through quote requests, even if those records were not published. This could lead to privacy breaches and misuse of personal data.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to personal data. GDPR requires protection of personal data, and HIPAA mandates safeguards for protected health information. A breach could result in legal penalties and reputational damage.

Mitigation Strategies

Immediately update the 'Request a Quote' plugin to the latest version if an update is available. If no update exists, consider disabling or removing the plugin until a patch is released. Restrict access to sensitive data and monitor for unusual activity related to quote submissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90988. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart